
The Cyber Safety Summit tackled a central question: who is accountable when a connected physical system is compromised? Engineers and policymakers are debating a new licensed discipline to manage the risk before a catastrophe forces the issue.
The Cyber Safety Summit held June 10 at the National Academy of Sciences in Washington, D.C., tackled a question that lacks a clear answer: who is professionally and legally accountable when a connected physical system is compromised? Cyber-physical risk, the summit made clear, is a life safety threat. No recognized engineer of record exists for it. No cyber safety standard of care has been codified.
That gap drove the summit's central debate. A growing number of engineers, insurers and policymakers argued for a new discipline – cyber safety engineering – to manage foreseeable hazards before they produce a catastrophe.
Engineering standards have historically been reactive. In the mid-1800s, fatal boiler explosions across America occurred almost every four days until a novel insurance product linked to quality inspection was established, eventually leading to the American Society of Mechanical Engineers boiler and pressure vessel code. The Great Chicago Fire killed roughly 300 people and destroyed 17,000 buildings, leading to building fire codes. The 1907 collapse of the Quebec Bridge, which killed 75 ironworkers due to a calculation error and engineering inexperience, helped establish the professional engineer as a guardian of public safety. Wyoming passed the first engineering licensure law in 1907; other states quickly followed.
John Kliem, director of federal strategy at Johnson Controls, expressed concern about following that pattern. “What scares me, is are we going to have to have a Pearl Harbor-level cybersecurity event to have more visibility?” he asked. Brian May, president of federal programs at Michael Baker International, agreed. “If a single incident causes a mass casualty event, our profession will be scrambling to develop standards under duress,” he said. “I believe we must start thoughtfully working this problem now, before we’re forced to account for a preventable catastrophe.”
Cyber-physical systems present the same conditions that drove every prior standard: foreseeable hazards, repeatable failure modes and potentially catastrophic consequences. The 2021 Colonial Pipeline attack, in which ransomware seized monitoring and billing systems connected to physical valves and meters, is one recent example. State-sponsored intrusions into U.S. infrastructure are ongoing. The open question is whether cyber safety engineering follows the historical pattern and waits for a disaster, or whether the profession moves first.
May asserted that the profession has reached a turning point. “Connected, smart technologies are present in nearly every new or retrofitted building system,” he said. “Practically speaking, engineers can no longer meet their professional obligation to deliver safe designs without considering and taking reasonable steps to mitigate cyber risk.” David Brearley of HDR noted that, in retrospect or in litigation after a cyber-physical incident, most parties would agree that the event was foreseeable. Yet no clear standards or accountability exist.
A gap in ownership was raised throughout the summit. Adam Gladsden, co-founder and CEO of construction insurer ConfigRisk, argued that the biggest risk issue is one of accountability and traceability. Adam Firestone, CEO of the quantum-secure communication platform SIX3RO, emphasized that the absence of a dedicated cybersecurity engineer requires decisive action. “We need to start saying that we will not be able to deliver unless we include a dedicated cybersecurity engineer,” he said. “That is one of the biggest things we can do for the engineering profession.”
Summit organizer and Building Cyber Security CEO Lucian Niemeyer offered two options: create a 25th professional engineering discipline or include cyber safety in the existing control systems professional engineer license. His concern with a standalone license is the time it will take to establish. Students could spend four years completing an engineering degree in a new field without a clear licensure path waiting for them at the end.
The National Council of Examiners for Engineering and Surveying administers the P.E. licensing exams used across states. The existing control systems P.E. exam already includes a security-focused section that covers access controls, risk assessment and verification of security levels. Summit organizers are proposing specific additions to that section: consequence-based classification for connected physical systems, a required technology registry documenting connected systems throughout a project's lifecycle, and formal cyber commissioning as a condition of project acceptance. A joint formal proposal by the National Academy of Engineering, National Academy of Construction, United Engineering Foundation and Building Cyber Security is targeted for submission to NCEES by October 2026. This is the first of seven phases recommended in the strategy framework through 2033.
Even with a licensure pathway, a new cyber safety engineering discipline will only take hold if there is market demand, professional society guidance and insurance ecosystem support. Firestone said the engineering industry currently isn't doing enough demand-generation work – employers who require cyber safety professionals and career paths that reward it – and needs to work directly with employers to create that pull rather than assuming it will materialize on its own.
Niemeyer pointed to Building Cyber Security's challenges in getting facility owners to care about the operational technology threat. Other safety issues such as electrical grounding or fire protection are assumed to be included in facility design and construction without owners stating them as required, he said. That is not the case with cyber threats.
In the meantime, student demand is emerging. Matthew Jablonski of George Mason University pointed to the school's cybersecurity engineering major, founded in 2015, as one of its fastest-growing programs. He said that industry demand was part of Virginia's State Council of Higher Education's approval process for the department to offer it as a distinct major. Given how quickly the cybersecurity field evolves, Brian Correia of the SANS Institute recommended that schools employ adjunct professors who are active in industry to keep curricula up to date.
Then there is the ethical obligation of engineers. When asked by Niemeyer what he would ask of engineering deans if he could, Acting Director of the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency Nick Anderson said, “we have the guilty knowledge of what the risk and potential threat are. Will you be able to look your family in the eye and explain to them why you knew this was a possibility and did nothing about it?”
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.